Version 6.0.0 - #1714
Draft
scarroll32 wants to merge 2 commits into
Draft
Version 6.0.0#1714scarroll32 wants to merge 2 commits into
scarroll32 wants to merge 2 commits into
Conversation
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Contributor
|
Thank you for all the work on this 🙇 |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Note
This PR was opened by Claude (Claude Code), acting on behalf of @scarroll32.
Draft: merge last, when 6.0.0 is released (planned on October 10, 2026, after a testing period against
main). Merging it and publishing a GitHub Release taggedv6.0.0publishes the gem; see the release flow.Bumps
Ransack::VERSIONto6.0.0. Closes #1640 when it merges.The text below is a draft of the release notes, compiled from the eight PRs of the 6.0.0 stack, ready to paste into the GitHub Release.
Security
created_at(1i)) in search params and drops malformed keys, closing a memory-exhaustion denial of service where a craftedq[created_at(100000000000i)]=1made the server allocate an array of that size. GHSA-vxc9-rm8f-p56j, reported by @connorshea. Also released as 5.0.1 and 4.4.2.q[...]condition key orq[s]sort value with thousands of_-separated segments was parsed in quadratic time and exhausted CPU. Not mitigated by attribute allowlisting. GHSA-j3f8-w227-4hh8. Also released as 5.0.2 and 4.4.3.Breaking changes
sqlite3exists for it. — Drop Ruby 3.1 support #1705, closes Drop Ruby 3.1 support in 6.0.0 #1686cont,start,endandmatchesare case-sensitive on PostgreSQL. They render asLIKE; thei_forms (i_cont, and the newi_startandi_end) areILIKE. Before, everyLIKEon PostgreSQL was rendered asILIKE, socontandi_contwere indistinguishable there. Nothing raises when a search turns case-sensitive, it just stops matching rows whose case differs, so check filters wired up by another library: ActiveAdmin's string filter offerscont,startandend. MySQL and SQLite are unchanged. — Detect the SQL dialect from the adapter class; drop the PostGIS dependency #1707, closes Ransack does not distinguish between "*_cont" for LIKE and "*_i_cont" for ILIKE with PostgreSQL #1421; Add i_start and i_end, the case-insensitive start and end predicates #1716, closes 6.0.0 feedback: cont/start/end became case-sensitive on PostgreSQL, and start/end have no i_ variant to move to #1715Polyamorousis gone;Ransack::Adapters::ActiveRecordis deprecated. The Active Record integration lives underRansack::ActiveRecord. The old constant still resolves with a deprecation warning and goes in 7.0;Polyamorous::JoinisRansack::ActiveRecord::Join;Ransack::SUPPORTS_ATTRIBUTE_ALIASandRansack::Context.for_class/for_objectare removed (see the resolver registry below). — Fold Polyamorous and Ransack::Adapters into Ransack::ActiveRecord #1706, closes Remove Polyamorous and Adapters namespaces #1625, Refactor Ransack modules and file structure #1631sorts=replaces instead of appending, sosearch.sorts = []clears the sorts;build_sortstill adds one. — Resolve ransack_alias through associations and compounds; sorts= replaces; scopes win in the writer #1711, closes Confusing sorts behavior #994ransack!,ignore_unknown_conditions = false) check more: an invalid sort raisesInvalidSearchErrorinstead of silently dropping the wholeORDER BY, and a condition name mixing_and_and_or_raises instead of applying the first combinator to every attribute. — Fix ten small, self-contained bugs from the issue triage #1708, closes ignore_unknown_conditions apply to non-allowed attributes for SORT too? #1427, Behavior when 'and' and 'or' are mixed in the symbol representing the target column #1019joins,left_outer_joins, an eager-loadedincludes, a previous search) no longer adds a second aliased join, so row counts from searches that hit the duplicate-join bug change. Ransack's own joins are now stashed inleft_outer_joins_values. — Reuse the joins a relation already has #1710attribute :x, :datetimeis honoured, and aDategiven for a datetime column means midnight inTime.zonerather than the server's system zone. — Fix ten small, self-contained bugs from the issue triage #1708, closes Date attributes aren't coerced as datetime when using "attribute attr, :datetime" in model #1028, Range of Dates Query converting to UTC before query #1436ransackable_scopes_skip_sanitize_argsreceivesfalseinstead of being skipped, so it can drive a yes/no/any select. — Fix ten small, self-contained bugs from the issue triage #1708, closes ransackable_scope with boolean value is skipped #1375Every item above is explained, with what to change, on the docs' Upgrading page.
Features
config.strong_parameters = true(off by default) trusts permittedActionController::Parametersas the authorization: the controller'spermitlist replacesransackable_attributes,ransackable_associationsandransortable_attributesfor that search;ransack(params, strong_parameters: true / false)overrides per search. Scopes stay gated, plain hashes and unpermitted params keep the model lists. — Let strong parameters authorize a model with no allowlist #1717, closes Extend 4.0.0 allow/deny listing with Strong Parameters #1403i_start,i_end, theirnot_opposites and_any/_allcompounds: case-insensitive starts-with and ends-with, mirroringi_cont(ILIKEon PostgreSQL,LOWER(col) LIKEelsewhere). — Add i_start and i_end, the case-insensitive start and end predicates #1716, closes 6.0.0 feedback: cont/start/end became case-sensitive on PostgreSQL, and start/end have no i_ variant to move to #1715config.dialectoverride for unknown adapters; the two database-specific decisions Ransack makes (LOWER()versusILIKE,CHAR_LENGTHversusLENGTH) now read the searched model's connection, so multi-database apps get the right SQL. — Detect the SQL dialect from the adapter class; drop the PostGIS dependency #1707, closes Explicitly support connection adapters #1639, Doesn't work correctly with active multiple databases #1407Ransack::Context.register: a resolver registry so an integration for another ORM can plug in without patching Ransack. — Fold Polyamorous and Ransack::Adapters into Ransack::ActiveRecord #1706ransack_aliasresolves through associations (person_termfor an alias onPerson) and inside_or_/_and_compounds; the alias itself no longer needs allowlisting, only its targets. — Resolve ransack_alias through associations and compounds; sorts= replaces; scopes win in the writer #1711, closes ransack_alias doesn't work in associations #1520, Add the ability to combine aliases #847, ransack_alias missing method not throwing #741predicate_name:is accepted alongsidepredicate:in long-form conditions, as the ransackers docs always said. — Fix ten small, self-contained bugs from the issue triage #1708, closes Ransacker params with alias for Passing Arguments #1009Bug fixes
LEFT OUTER JOINs onleft_outer_joins+ a condition on the same association (multiplied rows forhas_many), on chained searches, underincludes+pluck, and for nested pre-existing joins; wrong alias when the same table is joined twice;where(assoc: {...})alias not followed. — Reuse the joins a relation already has #1710, closes Ransack is not correctly overriding/using previous joins #824, Erroneous double-join when using pluck #1108, Duplicate (exponential) LEFT OUTER JOINS #1250, Ransack generates redundant left join statements #1433, SQL aliases are not supported when joining relations - at least with PG #1437, Single filter with multiple joins use the wrong association alias #1554i_contdid not lower a ransacker expression on databases withoutILIKE. — Detect the SQL dialect from the adapter class; drop the PostGIS dependency #1707, closes Custom ransackers not following case-insensitive behavior #1357from_id_or_to_id_eqon a polymorphic association raised "Polymorphic associations do not support computing the class";f.labelon an_of_Model_typeattribute raised the same. — Fix ten small, self-contained bugs from the issue triage #1708, closes Polymorphic filtering is inconsistent #1267, label for polymorphic association throws ArgumentError:"Polymorphic associations do not support computing the class" #1557Context#join_sourcesraised when the relation hadjoins(:x)(the merging-searches recipe). — Fix ten small, self-contained bugs from the issue triage #1708, closes NoMethodError: undefined method 'join_root' for an instance of Symbol #1659search_form_withdid not read field values back (Searchlackedrespond_to_missing?). — Fix ten small, self-contained bugs from the issue triage #1708ruby -wwarnings fromlib/. — Fix ten small, self-contained bugs from the issue triage #1708, closes Ruby 4.0 warnings: method redefinitions, unused variables, mismatched indentation #1669Documentation
Contextseam, the exact list of Active Record internals Ransack touches). Sections on databases and dialects, case sensitivity, negative predicates on collections, searching a relation that already has joins, aliases through associations, scopes andfalse, scopes andOR, searching everything, Action Text, encrypted attributes,EXISTSvia a scope, a fixed attribute with a predicate select. — Fold Polyamorous and Ransack::Adapters into Ransack::ActiveRecord #1706, Detect the SQL dialect from the adapter class; drop the PostGIS dependency #1707, Fix ten small, self-contained bugs from the issue triage #1708, Reuse the joins a relation already has #1710, Resolve ransack_alias through associations and compounds; sorts= replaces; scopes win in the writer #1711, Document what the issue triage found already answered #1712Internal
append_constraintsis called by arity, so both shapes Active Record has shipped work; Rails floor stays at 7.2. — Fold Polyamorous and Ransack::Adapters into Ransack::ActiveRecord #1706🤖 Generated with Claude Code